Workflow access control
Abstract
A software database access control system for providing a flexible method of designating areas of access and functions within the areas of access within a database system for users comprising: a user profile possessed by an authorized user, the user profile comprising permitted areas of access within a database system, and the permitted areas of the database system being accessible when certain predetermined conditions are met by the user profile; a firewall around the database system such that the database is accessible if the user profile allows access; and a virtual user being a logical entity and having sole authorization to alter the database system at the direction of the authorized user. An embodiment of the present invention also having audit trail capabilities for the tracking of requested changes to the database system, or actual changes performed to the database system.
Claims
exact text as granted — not AI-modified1 . A software database access control system comprising:
a) a plurality of user profiles, each of said user profiles comprising information relating to a condition or conditions which have to be met in order for certain areas of said database system to be accessible; b) a firewall around said database such that the database system is accessible if said user profile allows access; and c) a virtual user being a logical entity with sole authorization to alter said database system at the direction of a user whose user profile allows modification to said database system.
2 . A software database access control system as claimed in claim 1 wherein for a user employed by a proprietor of the database system said predetermined conditions include characteristics of the user's job function.
3 . A software database access control system as claimed in claim 2 wherein said characteristics are set by an entity, said entity being an organization, company or firm utilizing and controlling said system.
4 . A software database access control system as claimed in claim 2 wherein said characteristics are unique to an individual user.
5 . A software database access control system as claimed in claim 2 wherein said characteristics are unique to category of user and shared by more than one individual.
6 . A software database access control system as claimed in claim 2 wherein said proprietor is an owner, lessee, or other entity controlling the database system.
7 . A software database access control system as claimed in claim 1 wherein said predetermined conditions are based on a user's characteristics of user's application of database.
8 . A software database access control system as claimed in claim 1 wherein said predetermined conditions are based on a user's characteristics of a user's project requiring database access.
9 . A software database access control system as claimed in claim 1 wherein said user is a person or organization.
10 . A software database access control system as claimed in claim 1 wherein said user is a program, said program acting on behalf of a person or organization.
11 . A software database access control system as claimed in claim 1 wherein said user is an employee, vendor, contractor, customer, or government agency.
12 . A software database access control system as claimed in claim 1 wherein said database system is comprised of one database.
13 . A software database access control system as claimed in claim 1 wherein said database system is comprised of a plurality of databases located at a single location.
14 . A software database access control system as claimed in claim 1 wherein said database system is comprised of a plurality of databases located at a plurality of locations.
15 . A software database access control system as claimed in claim 1 further comprising an audit trail, said audit trail comprising a record of requests made to the virtual user for changes to the database system.
16 . A software database access control system as claimed in claim 16 wherein said record of requests comprising a record of the user requesting the change, the type of change requested, the date and time the change requested, the database said change was requested for and if the change was executed by the virtual user.
18 . A software database access control system as claimed in claim 1 further comprising an audit trail, said audit trail comprising a record of changes made to the database system.
19 . A software database access control system as claimed in claim 18 wherein said record of requests comprising a record of: the user requesting the change, the type of change made, the date and time the change was executed, and the database changed.
20 . A software database access control system as claimed in claim 1 further comprising:
d) at least one additional condition connected to said firewall; and
e) at least one additional characteristic connected with at least one of said user profiles;
wherein said additional condition must be satisfied by said additional characteristic prior to access or modification of said database system being accomplished.
21 . A software database access control system as claimed in claim 20 wherein said additional characteristic is a user's personal identity, department, division or company.
22 . A software database access control system to control access to a database system for a plurality of users comprising:
a) a plurality of user profiles connected respectively with the plurality of users; b) a plurality of roles, said roles being connected with one or more of the user profiles; c) a plurality of functions said functions being connected with one or more of the roles; wherein a user cannot perform a given function on or to the database system unless the user has access to the function by having its user profile being connected with a role which is connected with the function.
23 . The system according to claim 22 wherein some of the connections between the roles and the functions they contain are conditional.
24 . A software database access control system to control access to a database system for a plurality of users comprising:
a) a plurality of user profiles connected respectively with the plurality of users; b) a plurality of roles, said roles being connected with one or more of the user profiles; c) a plurality of functions said functions being connected with one or more of the roles; d) a virtual user being a logical entity with sole authorization to access or alter said database wherein said virtual user will only perform a specific function if the user requesting such a function is connected to a role which is connected to the function.Join the waitlist — get patent alerts
Track US2002083059A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.